Learn · Guide · 5 min read

External vulnerability scan vs. penetration test

If you've been quoted thousands of dollars for a "penetration test," it's worth knowing exactly what you're buying, and whether a monthly scan does the job for a fraction of the cost.

What an external vulnerability scan does

An automated external scan looks at your internet-facing systems the way an attacker's first pass would: which ports are open, whether your encryption is current, what your web server reveals, whether your software has known vulnerabilities, and whether your email and logins are protected. It's fast, repeatable, and affordable enough to run every month.

What a penetration test adds

A penetration test puts a skilled human in the loop. They take the weaknesses a scan finds and try to chain them together, use social engineering, and think creatively the way a real attacker would. It's deeper, produces a narrative of how far someone could get, and it's correspondingly expensive and occasional.

Which do you need?

For most small and mid-sized organizations, the honest answer is both, at different rhythms:

The mistake is treating a once-a-year assessment as your only line of sight. It's a photo when what you need is a heartbeat monitor: the day after the assessment, someone changes a firewall rule and you're blind again until next year.

Where Torva fits

Torva Edge is the monthly heartbeat: continuous external scanning with plain-English fixes and a score you can track. When you do commission a penetration test, you'll walk in with the easy findings already fixed, so the expert's time goes toward the deep work only a human can do.


Want this checked for you automatically? Start a free Torva account and we'll scan for this and dozens of other issues every month, with the fixes spelled out.